Suspicious Boot Configuration Change Disabling Integrity Checks

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-28
Updated
2026-09-28

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects bcdedit modifying boot load options to disable driver signature integrity checks, a prerequisite for loading unsigned or malicious kernel drivers. This was observed in the ReadText34 ransomware incident alongside bring-your-own-vulnerable-driver activity. Disabling integrity checks lets attackers load kernel-level tooling to tamper with security controls.

Related detections9 linkedT1211 — drag to rearrange
Malicious Secure Boot Bypass Files Dropped to EFI Partition
Suspicious Dell ControlVault DLL Load by Unexpected Process (ReVault)
Suspicious Vulnerable ASUS AsIO3.sys Driver Load
Suspicious Vulnerable Driver Load for BYOVD Abuse by DragonForce Ransomware (via driver_load)
Suspicious Staged Payload Execution from User Downloads or Pictures Folder
Malicious Vulnerable Driver Deployment for EDR Termination via file_event
Possible PAN-OS Auth Bypass via Double-Encoded Path Traversal to ztp_gate (CVE-2025-0108)
Malicious Bring-Your-Own-Vulnerable-Driver Load By BlackByte
Windows Process Command Lines Writing Malicious Files to C:\Windows\Fonts
Suspicious Boot Configuration Change Disabling Integrity Checks
Pivot detection · T1211 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.